|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
how to get defaced phpbb back? (knowing admin pw) |
|
Posted: Sat May 13, 2006 4:40 pm |
|
|
hahi |
Beginner |
|
|
Joined: May 13, 2006 |
Posts: 3 |
|
|
|
|
|
|
|
hi,
I want to get access to a phpbb 2.0.4 that has been defaced (oh yeah surprise ).
I'm not the admin of this board, and admin surely won't come back too soon.
Topics are still available, there's only a message that the forum has been defaced and everything is closed. Registering isn't possible as admin has to activate accounts now and private messaging is disabled.
I have already got the admin password as well as the mysql access data, but i don't know how to go on from there .
If i try to log in as admin, it gives me a blank page. Anyway, the pw seems to be correct as i can see admin as logged in for the next some minutes.
the /admin/index.php gives me a blank page as well, so i don't see a chance for getting inside there somewhere.
I do have the mysql data, too, but mysql control center says that my host isn't allowed to connect to this database, so i assume that remote access is disabled, and i have no idea where the phpmyadmin could be, if there is one.
As i'm new to hacking boards, i don't exactly know what the hacker (or cracker if you like) did there exactly.
So i hope that someone here has an idea how to get that board back, as i think that has to be possible...
Thanks a lot for any answers. |
|
|
|
|
|
|
|
|
Posted: Sun May 14, 2006 7:38 pm |
|
|
SicKn3sS |
Regular user |
|
|
Joined: Apr 16, 2006 |
Posts: 14 |
|
|
|
|
|
|
|
go to illectric.com and select domain whois in the search, then enter the address of the site there and you should find some servers, then try and match up the user name and password and you can get access to their ftp and sql servers. |
|
|
|
|
|
|
|
|
Posted: Sun May 14, 2006 9:30 pm |
|
|
hahi |
Beginner |
|
|
Joined: May 13, 2006 |
Posts: 3 |
|
|
|
|
|
|
|
SicKn3sS wrote: | go to illectric.com and select domain whois in the search, then enter the address of the site there and you should find some servers, then try and match up the user name and password and you can get access to their ftp and sql servers. |
i don't get that... what servers should i find there? it just gives me the whois data, doesn't it? and that only of the topdomain, the forum is in a folder of a subdomain...
by the way, if the config.php says that the mysql database is at localhost, does that mean that it's on the subdomain or on the topdomain?
no chance of logging into the forum with admin account and somehow avoiding these blank pages?
what was changed there that caused this shit? |
|
|
|
|
|
|
|
|
Posted: Wed May 17, 2006 2:48 pm |
|
|
hahi |
Beginner |
|
|
Joined: May 13, 2006 |
Posts: 3 |
|
|
|
|
|
|
|
hahahaha, i found a way by myself
life can sometimes be so simple...
the cookie settings were set to wrong, so logging into the forum was impossible. however, i found a way to log in anyway
finally, at least the admin-forum-access... but now let's see if there is a way to get into the ftp account. need to update this 2.0.4 shit
/edit btw, why do i have 3 posts but only 2 are counted? not that i would bother, but maybe this is a bug? |
|
|
|
|
Posted: Wed May 17, 2006 2:54 pm |
|
|
waraxe |
Site admin |
|
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
|
|
|
|
hahi wrote: |
/edit btw, why do i have 3 posts but only 2 are counted? not that i would bother, but maybe this is a bug? |
Yep, this is some kinda bug, it is happening sometimes. Something is messy in phpbb source code
I will correct this counter manually ... |
|
|
|
|
Posted: Thu May 18, 2006 4:45 am |
|
|
Chb |
Valuable expert |
|
|
Joined: Jul 23, 2005 |
Posts: 206 |
Location: Germany |
|
|
|
|
|
|
Many FTP clients have got a proxy mode. But it's up to you to find a good SOCKS proxy for using for FTP. |
|
|
|
|
www.waraxe.us Forum Index -> PhpBB
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|